File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- .env:6
- Evidence
PRIVATE_KEY=[REDACTED]
Security audit
Security checks for vulnerabilities and agentic risk
The todo tools are simple, but the package includes a live-looking wallet private key and billing/private-key setup that is not clearly reflected in the basic metadata.
Review this plugin carefully before installing. The todo functionality is narrow and local, but the packaged .env private key and wallet billing configuration are significant red flags. Prefer a corrected release with no bundled secrets, clear billing documentation, and a rotated/removed exposed key.
Detected: suspicious.exposed_secret_literal
PRIVATE_KEY=[REDACTED]